<div>Thanks Wes, I will try this and post the outcome.</div>
<div><br><br> </div>
<div><span class="gmail_quote">On 9/12/06, <b class="gmail_sendername">Wes Sisk</b> <<a href="mailto:wsisk@cisco.com">wsisk@cisco.com</a>> wrote:</span>
<blockquote class="gmail_quote" style="PADDING-LEFT: 1ex; MARGIN: 0px 0px 0px 0.8ex; BORDER-LEFT: #ccc 1px solid">I believe this is what you need:<br><a href="http://www.cisco.com/en/US/partner/products/sw/secursw/ps2120/products_configuration_guide_chapter09186a008017278b.html#wp1063720">
http://www.cisco.com/en/US/partner/products/sw/secursw/ps2120/products_configuration_guide_chapter09186a008017278b.html#wp1063720</a><br><br>and this, but with inside/outsider reversed:<br><a href="http://www.ciscotaccc.com/kaidara-advisor/security/showcase?case=K72511039">
http://www.ciscotaccc.com/kaidara-advisor/security/showcase?case=K72511039</a><br><br>/Wes<br><br>Manoj Kalpage wrote:<br>> Wes,<br>> Thank You for the reply. Yes I have NAT on my PIX. Regarding DNS fixup,<br>> do i need additional settings on my PIX except the fixup protocol dns
<br>> maximum-length 512 ?<br>><br>> Best Regards,<br>> Manoj<br>><br>><br>> ----- Original Message -----<br>> *From:* Wes Sisk <mailto:<a href="mailto:wsisk@cisco.com">wsisk@cisco.com</a>
><br>> *To:* Manoj Kalpage <mailto:<a href="mailto:manoj.kalpage@gmail.com">manoj.kalpage@gmail.com</a>><br>> *Cc:* ciscovoip Voip <mailto:<a href="mailto:cisco-voip@puck.nether.net">cisco-voip@puck.nether.net
</a>> ; Stu<br>> Packett <mailto:<a href="mailto:SPackett@fenwick.com">SPackett@fenwick.com</a>><br>> *Sent:* Sunday, September 10, 2006 10:28 PM<br>> *Subject:* Re: [cisco-voip] Internet IP phone connect through PIX
<br>> Firewall<br>><br>> Manoj,<br>><br>> Are you doing NAT on your PIX? If so, you will need special CM+PIX<br>> config.<br>><br>> phones download SEP<mac>.cnf.xml from TFTP server. Inside this XML
<br>> file is a listing of which CM servers the phone should register to<br>> using SCCP. This file also tells the phone what TCP port to use for<br>> the SCCP communication. The CM servers are listed in this by name
<br>> or IP address based on how your CM is configured under system->server.<br>><br>> For NAT traversal, your CM will have to be configured using host<br>> names. Your PIX will have to do DNS fixup. Your phone will receive
<br>> the name <a href="http://cm1.manoj.com">cm1.manoj.com</a>. the phone must do DNS lookup on this and<br>> receive the external address of your CM server.<br>><br>> Otherwise, you must use a valid internet address for the IP of your
<br>> CM server.<br>><br>> /Wes<br>> On Sep 9, 2006, at 3:41 PM, Stu Packett wrote:<br>><br>> Sorry, I have never tried without the VPN. I thought best practice<br>> was to use the VPN because it was not advised to put the CCM on the
<br>> public internet. If you do get your config working, I'd like to get<br>> a copy of your config just for reference. Thanks.<br>><br>> ------------------------------------------------------------------------
<br>> *From:* Manoj Kalpage [mailto:<a href="mailto:manoj.kalpage@gmail.com">manoj.kalpage@gmail.com</a>]<br>> *Sent:* Saturday, September 09, 2006 12:20 AM<br>> *To:* Stu Packett<br>> *Cc:* <a href="mailto:cisco-voip@puck.nether.net">
cisco-voip@puck.nether.net</a> <mailto:<a href="mailto:cisco-voip@puck.nether.net">cisco-voip@puck.nether.net</a>><br>> *Subject:* Re: [cisco-voip] Internet IP phone connect through PIX<br>> Firewall<br>
><br>> Stu,<br>> Thank you for the reply, I use windows 2003 DHCP server for my<br>> phones in LAN but I can get my outside phone connect to CCM through<br>> internet. Do you have IP phones connect to your CCM through internet
<br>> without using VPN?<br>><br>> Thanks,<br>> Manoj<br>><br>><br>><br>> On 9/9/06, *Stu Packett* <<a href="mailto:SPackett@fenwick.com">SPackett@fenwick.com</a><br>> <mailto:
<a href="mailto:SPackett@fenwick.com">SPackett@fenwick.com</a>>> wrote:<br>><br>> Manoj:<br>> Is your PIX giving out DHCP addresses? On my PIX 501, I have it<br>> setup as a DHCP server and these are my DHCP commands:
<br>><br>> dhcpd address xxx.xxx.xxx.xxx<br>> dhcpd dns xxx.xxx.xxx.xxx xxx.xxx.xxx.xxx<br>> dhcpd wins xxx.xxx.xxx.xxx xxx.xxx.xxx.xxx<br>> dhcpd lease 36000<br>> dhcpd ping_timeout 750
<br>> dhcpd domain <a href="http://internaldomain.com">internaldomain.com</a> <<a href="http://internaldomain.com/">http://internaldomain.com/</a>><br>> dhcpd option 150 ip xxx.xxx.xxx.xxx <--TFTP address
<br>> dhcpd enable inside<br>><br>> ------------------------------------------------------------------------<br>> *From:* <a href="mailto:cisco-voip-bounces@puck.nether.net">cisco-voip-bounces@puck.nether.net
</a><br>> <mailto:<a href="mailto:cisco-voip-bounces@puck.nether.net">cisco-voip-bounces@puck.nether.net</a>> [mailto:<br>> <a href="mailto:cisco-voip-bounces@puck.nether.net">cisco-voip-bounces@puck.nether.net
</a><br>> <mailto:<a href="mailto:cisco-voip-bounces@puck.nether.net">cisco-voip-bounces@puck.nether.net</a>>] *On Behalf Of<br>> *Manoj Kalpage<br>> *Sent:* Friday, September 08, 2006 4:18 AM
<br>> *To:* <a href="mailto:cisco-voip@puck.nether.net">cisco-voip@puck.nether.net</a> <mailto:<a href="mailto:cisco-voip@puck.nether.net">cisco-voip@puck.nether.net</a>><br>> *Subject:* [cisco-voip] Internet IP phone connect through PIX
<br>> Firewall<br>><br>><br>> Hi All,<br>> Does any one has configured PIX firewall to connect internet IP<br>> phones to Call Manager. I have configure firewall to open all
<br>> the port which CCM need but still no luck. Bellow is the config<br>> of my PIX. Am i missing anything?<br>><br>> Here is the link I refered to open the TCP and UDP Ports<br>><br>
> <a href="http://www.cisco.com/application/pdf/en/us/guest/products/ps5820/c1693/ccmigration_09186a0080536eae.pdf">http://www.cisco.com/application/pdf/en/us/guest/products/ps5820/c1693/ccmigration_09186a0080536eae.pdf
</a><br>><br>> Thank you in advance.<br>> Manoj<br>><br>> :<br>> PIX Version 6.3(5)<br>> interface ethernet0 auto<br>> interface ethernet1 auto<br>> nameif ethernet0 outside security0
<br>> nameif ethernet1 inside security100<br>> enable password u2zabJUOK.TTL3K1 encrypted<br>> passwd 1P5CrRl.dL8Oe4k2 encrypted<br>> hostname PBXLPIX01<br>> domain-name
<a href="http://pbxl.jp">pbxl.jp</a> <<a href="http://pbxl.jp/">http://pbxl.jp/</a>><br>> clock timezone JST 9<br>> fixup protocol dns maximum-length 512<br>> fixup protocol ftp 21<br>
> fixup protocol h323 h225 1720<br>> fixup protocol h323 ras 1718-1719<br>> fixup protocol http 80<br>> fixup protocol pptp 1723<br>> fixup protocol rsh 514<br>> fixup protocol rtsp 554
<br>> fixup protocol sip 5060<br>> fixup protocol sip udp 5060<br>> fixup protocol skinny 2000<br>> fixup protocol smtp 25<br>> fixup protocol snmp 161<br>> fixup protocol sqlnet 1521
<br>> fixup protocol tftp 69<br>> names<br>> object-group service outbound-tcp tcp<br>> port-object eq www<br>> port-object eq https<br>> port-object eq smtp
<br>> port-object eq ftp<br>> port-object eq pop3<br>> port-object eq imap4<br>> port-object eq domain<br>> port-object eq 123<br>> port-object eq ssh
<br>> port-object eq citrix-ica<br>> object-group service outbound-udp udp<br>> port-object eq domain<br>> port-object eq ntp<br>> object-group service mail-inbound tcp
<br>> port-object eq www<br>> port-object eq https<br>> port-object eq smtp<br>> object-group service VoIP-udp udp<br>> port-object range 16384 32768<br>> port-object eq tftp
<br>> object-group service VoIP-tcp tcp<br>> port-object eq 3804<br>> port-object eq 2443<br>> port-object eq 2000<br>> port-object eq www<br>> port-object eq 69
<br>> port-object eq https<br>> access-list 102 permit tcp <a href="http://172.16.0.0">172.16.0.0</a> <<a href="http://172.16.0.0/">http://172.16.0.0/</a>><br>> <a href="http://255.255.0.0">
255.255.0.0</a> <<a href="http://255.255.0.0/">http://255.255.0.0/</a>> any object-group VoIP-tcp<br>> access-list 102 permit udp <a href="http://172.16.0.0">172.16.0.0</a> <<a href="http://172.16.0.0/">
http://172.16.0.0/</a>><br>> <a href="http://255.255.0.0">255.255.0.0</a> <<a href="http://255.255.0.0/">http://255.255.0.0/</a>> any object-group VoIP-udp<br>> access-list 102 permit tcp <a href="http://172.16.0.0">
172.16.0.0</a> <<a href="http://172.16.0.0/">http://172.16.0.0/</a>><br>> <a href="http://255.255.0.0">255.255.0.0</a> <<a href="http://255.255.0.0/">http://255.255.0.0/</a>> any object-group outbound-tcp
<br>> access-list 102 permit udp <a href="http://172.16.0.0">172.16.0.0</a> <<a href="http://172.16.0.0/">http://172.16.0.0/</a>><br>> <a href="http://255.255.0.0">255.255.0.0</a> <<a href="http://255.255.0.0/">
http://255.255.0.0/</a>> any object-group outbound-udp<br>> access-list 101 permit tcp any host <a href="http://210.81.12.195">210.81.12.195</a><br>> <<a href="http://210.81.12.195/">http://210.81.12.195/
</a>> object-group mail-inbound<br>> access-list 101 permit tcp any host <a href="http://210.81.12.196">210.81.12.196</a><br>> <<a href="http://210.81.12.196/">http://210.81.12.196/</a>> object-group VoIP-tcp
<br>> access-list 101 permit udp any host <a href="http://210.81.12.196">210.81.12.196</a><br>> <<a href="http://210.81.12.196/">http://210.81.12.196/</a>> object-group VoIP-udp<br>> access-list 101 permit tcp any host
<a href="http://210.81.12.197">210.81.12.197</a><br>> <<a href="http://210.81.12.197/">http://210.81.12.197/</a>> object-group VoIP-tcp<br>> access-list 101 permit udp any host <a href="http://210.81.12.197">
210.81.12.197</a><br>> <<a href="http://210.81.12.197/">http://210.81.12.197/</a>> object-group VoIP-udp<br>><br>> pager lines 24<br>> logging on<br>> logging trap informational
<br>> logging host inside <a href="http://172.16.0.26">172.16.0.26</a> <<a href="http://172.16.0.26/">http://172.16.0.26/</a>><br>> logging host inside <a href="http://172.16.0.12">172.16.0.12</a>
<<a href="http://172.16.0.12/">http://172.16.0.12/</a>><br>> icmp permit any unreachable outside<br>> icmp permit any outside<br>> mtu outside 1500<br>> mtu inside 1500<br>
> ip address outside xxx.xxx.xxx.xxx <a href="http://255.255.255.240">255.255.255.240</a><br>> <<a href="http://255.255.255.240/">http://255.255.255.240/</a>><br>> ip address inside
<a href="http://172.16.0.2">172.16.0.2</a> <<a href="http://172.16.0.2/">http://172.16.0.2/</a>> <a href="http://255.255.0.0">255.255.0.0</a><br>> <<a href="http://255.255.0.0/">http://255.255.0.0/</a>
><br>><br>> ip audit info action alarm<br>> ip audit attack action alarm<br>> ip local pool pbxlpool 10.1.0.100-10.1.0.200<br>> pdm locationxxx.xxx.xxx.xxx <a href="http://255.255.255.255">
255.255.255.255</a><br>> <<a href="http://255.255.255.255/">http://255.255.255.255/</a>> outside<br>><br>> pdm history enable<br>> arp timeout 14400<br>> global (outside) 1 interface
<br>> nat (inside) 0 access-list VPNREMOTE<br>> nat (inside) 1 <a href="http://172.16.0.0">172.16.0.0</a> <<a href="http://172.16.0.0/">http://172.16.0.0/</a>> <a href="http://255.255.0.0">255.255.0.0
</a><br>> <<a href="http://255.255.0.0/">http://255.255.0.0/</a>> 0 0<br>> static (inside,outside) xxx.xxx.xxx.xxx xxx.xxx.xxx.xxx netmask<br>> <a href="http://255.255.255.255">255.255.255.255
</a> <<a href="http://255.255.255.255/">http://255.255.255.255/</a>>0 1000<br>> static (inside,outside) xxx.xxx.xxx.xxx xxx.xxx.xxx.xxx netmask<br>> <a href="http://255.255.255.255">255.255.255.255
</a> <<a href="http://255.255.255.255/">http://255.255.255.255/</a>> 0 1000<br>> static (inside,outside) xxx.xxx.xxx.xxx xxx.xxx.xxx.xxx netmask<br>> <a href="http://255.255.255.255">255.255.255.255
</a> <<a href="http://255.255.255.255/">http://255.255.255.255/</a>> 0 1000<br>><br>> access-group 101 in interface outside<br>> access-group 102 in interface inside<br>> route outside
<a href="http://0.0.0.0">0.0.0.0</a> <<a href="http://0.0.0.0/">http://0.0.0.0/</a>> <a href="http://0.0.0.0">0.0.0.0</a><br>> <<a href="http://0.0.0.0/">http://0.0.0.0/</a>> <a href="http://210.81.12.193">
210.81.12.193</a> <<a href="http://210.81.12.193/">http://210.81.12.193/</a>> 1<br>><br>> timeout xlate 3:00:00<br>> timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 rpc 0:10:00<br>> h225 1:00:00
<br>> timeout h323 0:05:00 mgcp 0:05:00 sip 0:30:00 sip_media 0:02:00<br>> timeout sip-disconnect 0:02:00 sip-invite 0:03:00<br>> timeout uauth 0:05:00 absolute<br>> aaa-server TACACS+ protocol tacacs+
<br>> aaa-server TACACS+ max-failed-attempts 3<br>> aaa-server TACACS+ deadtime 10<br>> aaa-server RADIUS protocol radius<br>> aaa-server RADIUS max-failed-attempts 3<br>> aaa-server RADIUS deadtime 10
<br>> aaa-server LOCAL protocol local<br>><br>> aaa authentication ssh console LOCAL<br>><br>> http <a href="http://172.16.0.12">172.16.0.12</a> <<a href="http://172.16.0.12/">http://172.16.0.12/
</a>> <a href="http://255.255.255.255">255.255.255.255</a><br>> <<a href="http://255.255.255.255/">http://255.255.255.255/</a>> inside<br>><br>> snmp-server host inside <a href="http://172.16.0.12">
172.16.0.12</a> <<a href="http://172.16.0.12/">http://172.16.0.12/</a>><br>> snmp-server location pbxl-pix-datacentre<br>><br>> snmp-server community pbxl<br>> snmp-server enable traps
<br>> floodguard enable<br>><br>> telnet <a href="http://172.16.0.0">172.16.0.0</a> <<a href="http://172.16.0.0/">http://172.16.0.0/</a>> <a href="http://255.255.0.0">255.255.0.0</a><br>> <
<a href="http://255.255.0.0/">http://255.255.0.0/</a>> inside<br>> telnet <a href="http://192.168.0.0">192.168.0.0</a> <<a href="http://192.168.0.0/">http://192.168.0.0/</a>> <a href="http://255.255.255.0">
255.255.255.0</a><br>> <<a href="http://255.255.255.0/">http://255.255.255.0/</a>> inside<br>> telnet timeout 60<br>> ssh <a href="http://210.101.94.211">210.101.94.211</a> <<a href="http://210.101.94.211/">
http://210.101.94.211/</a>> <a href="http://255.255.255.255">255.255.255.255</a><br>> <<a href="http://255.255.255.255/">http://255.255.255.255/</a>> outside<br>> ssh <a href="http://0.0.0.0">
0.0.0.0</a> <<a href="http://0.0.0.0/">http://0.0.0.0/</a>> <a href="http://0.0.0.0">0.0.0.0</a> <<a href="http://0.0.0.0/">http://0.0.0.0/</a>> outside<br>> ssh <a href="http://172.16.0.12">172.16.0.12
</a> <<a href="http://172.16.0.12/">http://172.16.0.12/</a>> <a href="http://255.255.255.255">255.255.255.255</a><br>> <<a href="http://255.255.255.255/">http://255.255.255.255/</a>> inside<br>> ssh
<a href="http://172.16.0.0">172.16.0.0</a> <<a href="http://172.16.0.0/">http://172.16.0.0/</a>> <a href="http://255.255.0.0">255.255.0.0</a><br>> <<a href="http://255.255.0.0/">http://255.255.0.0/</a>
> inside<br>> ssh <a href="http://192.168.1.0">192.168.1.0</a> <<a href="http://192.168.1.0/">http://192.168.1.0/</a>><a href="http://255.255.255.0">255.255.255.0</a><br>> <<a href="http://255.255.255.0/">
http://255.255.255.0/</a>> inside<br>><br>> ssh timeout 60<br>> console timeout 0<br>> PBXLPIX01(config)#<br>> PBXLPIX01(config)#<br>><br>><br>><br>> _______________________________________________
<br>> cisco-voip mailing list<br>> <a href="mailto:cisco-voip@puck.nether.net">cisco-voip@puck.nether.net</a> <mailto:<a href="mailto:cisco-voip@puck.nether.net">cisco-voip@puck.nether.net</a>><br>>
<a href="https://puck.nether.net/mailman/listinfo/cisco-voip">https://puck.nether.net/mailman/listinfo/cisco-voip</a><br>><br></blockquote></div><br>